SYN Cookies in Firewalls and Load Balancers
A commonly used distributed denial of service (DDoS) attack is known as SYN-flooding. In this type of attack, the attacker sends a series of TCP SYN packets that typically originate from spoofed IP addresses. The constant flood of SYN packets can prevent servers within the data center from handling legitimate connection requests. You can use firewalls and security appliances such as the Cisco ASA and the Cisco PIX enabled with the SYN cookies algorithm to combat SYN flood attacks. In large data centers, the Cisco Firewall Services Module (FWSM), for the Catalyst 6500 series switches, is typically used for this same purpose. Figure 10-1 demonstrates how TCP synchronization message (SYN) cookies work in the Cisco Adaptive Security Appliance (ASA), the Cisco PIX, and the FWSM for the Cisco Catalyst 6500 switches. In this example, a Cisco FWSM is used.
Figure 10-1 SYN Cookies in FWSM
Figure 10-1 SYN Cookies in FWSM
Client FWSM Server
Client FWSM Server
The following steps are illustrated in Figure 10-1:
1 A client machine attempts a TCP connection to a web server behind the FWSM and sends the initial SYN packet to the firewall.
2 When the embryonic (half-open) connection limit is reached, the Cisco ASA, Cisco PIX, or Cisco FWSM can act as a proxy for the server and generate a SYN-ACK response to the client SYN request. The SYN-ACK reply has a "cookie" in the sequence (SEQ) field of the TCP header. The cookie is a message digest 5 algorithm (MD5) authentication of the source and destination IP addresses and port numbers. All the connection requests are rebuilt from these cookies.
3 The acknowledgement (ACK) packet SEQ field has the value of the cookie+1. In this case, when the FWSM receives an ACK from the client, it "authenticates" the client and allows the connection to the server.
4 The FWSM sends its own SYN packet to the server.
5 The server replies with an ACK.
6 The FWSM sends its SYN-ACK to the server, and the connection is built.
On the Cisco FWSM, you can use the show np command to view SYN cookie statistics.
Example 10-1 shows the output of the show np 2 syn command on an FWSM.
Example 10-1 Output of show np 2 syn Command
FWSM# show np 2 syn
Fast Path Syn Cookie Statistics Counters (NP-2)
SYN_COOKIE: Syn cookie secret wheel index : 16
SYN_COOKIE: Total number of SYNs intercepted : 231356987
SYN_COOKIE: Total number of ACKs intercepted : 204
SYN_COOKIE: Total number of ACKs dropped after lookup : 0
|
SYN |
COOKIE |
Total number of ACKs successfully validated |
193 |
|
SYN |
COOKIE |
Total number of ACKs Dropped: Secret Expired |
11 |
|
SYN |
COOKIE |
Total number of ACKs Dropped: Invalid Sequence : |
0 |
|
SYN |
COOKIE |
Total number of Syn Cookie Entries inserted by NP3 |
12 |
|
SYN |
COOKIE: |
ACKs dropped: Syn cookie ses not yet established : |
0 |
|
SYN |
COOKIE: |
Leaf allocation failed : |
0 |
|
SYN |
COOKIE: |
Leaf insertion failed : |
2088 |
In the highlighted line in Example 10-1, you can see that the total number of intercepted SYN packets is 231356987. This is most definitely indicative of a SYN flood.
Load-balancing solutions such as the Cisco Content Switching Module (CSM) also support SYN cookies. You can deploy the CSM in inline mode or one-arm mode. Figure 10-2 illustrates a CSM configured in inline mode. Traffic from certain applications cannot be load-balanced because of the nature of those applications. In Figure 10-2, the traffic that cannot be load-balanced is labeled as direct traffic.
Figure 10-2 CSM in Inline Mode
Figure 10-2 CSM in Inline Mode
In Figure 10-2, the CSM is configured with both physical interfaces that are connected to the network with all traffic passing through the CSM. Figure 10-3 illustrates the one-arm CSM design.
The CSM uses a virtual IP address. In a "one-arm" design, you can combine it with a Cisco FWSM. One of the major benefits of using a CSM one-arm design in combination with the Cisco FWSM is that the CSM protects against DoS attacks directed at its virtual IP address, and the Cisco FWSM protects against attacks directed at non-load-balanced servers.
The use of SYN cookies has certain limitations. For example, SYN cookies cannot carry TCP options that are set up in SYN packets; SYN cookies can carry only an encoding of the maximum segment size (MSS) value of the server. Some TCP options are used for performance and scalability (for example, large windows, selective acknowledgement, and so on). Another limitation of SYN cookies is that they do not protect against established connection attacks.
Figure 10-3 CSM in One-Arm Mode
Figure 10-3 CSM in One-Arm Mode
NOTE Established connection attacks are attacks that exploit vulnerabilities after a connection has been established such as a buffer overflow to a specific application.
Continue reading here: Cisco Net Flow in the Data Center
Was this article helpful?